Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
09 Nov 2017Consorzio di Polizia locale Valle AgnoConsorzio di Polizia locale Valle Agno was fined EUR 10,400 by the Garante for deploying a mobile video surveillance system and a localization system on employee devices without the required information or prior notification. The authority found this to be a breach of data protection rules.ITGaranteGDPR€10,400
09 Nov 2017Società Alberghi Circeo s.r.l.Società Alberghi Circeo s.r.l. was fined 10,000 EUR by the Garante. The authority found that the company failed to appoint data processing officers for employees handling personal data, in breach of Article 33 of the Italian Data Protection Code.ITGaranteGDPR€10,000
09 Nov 2017GSG Enterprise società cooperativa edileGSG Enterprise was fined EUR 96,000 by the Garante for using the personal data of car owners to demand payment for services that were neither performed nor requested. The case concerns unlawful processing of personal data for debt-collection style demands.ITGaranteGDPR€96,000
09 Nov 2017A.M.A.CO. s.p.a.A.M.A.CO. s.p.a. was fined by the Garante for installing non-compliant video surveillance and geolocation systems on its vehicles. The authority found that these measures breached data protection rules.ITGaranteGDPR€22,400
26 Oct 2017M&M Centro analisi s.r.l.M&M Centro analisi s.r.l. was fined by the Garante 20,000 EUR for failing to notify the processing of sensitive health data. The obligation arose under the Italian Data Protection Code.ITGaranteGDPR€20,000
26 Oct 2017Verde Luna s.a.s. di Antonietta Minnicelli & C.Verde Luna s.a.s. was fined EUR 20,000 by the Garante. The sanction concerned the company’s failure to provide information requested by the supervisory authority in a data protection matter.ITGaranteGDPR€20,000
25 Oct 2017TICKETMASTER SPAIN S.A.Ticketmaster Spain S.A. was fined 17,000 EUR by the AEPD for failing to provide adequate information and obtain valid consent for the use of cookies on its website. The authority found that this conduct breached data protection and privacy rules.ESAEPDePrivacy€17,000
25 Oct 2017EDITORIAL ECOPRENSA, S.A.EDITORIAL ECOPRENSA, S.A. was fined EUR 15,000 by the AEPD for failing to register user data files with the data protection authority, providing inconsistent privacy information, and irregularly sharing data with third parties. The case indicates deficiencies in core transparency obligations and control over personal data disclosures.ESAEPDePrivacy€15,000
19 Oct 2017Grant Change s.r.l.Grant Change s.r.l. was fined €32,000 by the Italian data protection authority, Garante. The penalty concerned the sending of promotional SMS messages and emails without valid consent from recipients, in breach of data protection rules.ITGaranteGDPR€32,000
19 Oct 2017A.N.S.A. s.r.l.A.N.S.A. s.r.l. was fined for processing personal health data without notifying the Garante. The authority found a breach of Articles 37 and 38 of the Italian Privacy Code.ITGaranteGDPR€20,000
19 Oct 2017Pittaluga servizio containers S.p.A.Pittaluga servizio containers S.p.A. was fined by the Garante €8,000 for using a geolocation system on its vehicles without full compliance with data protection rules. The case concerned improper processing of location data linked to vehicles or employees.ITGaranteGDPR€8,000
12 Oct 2017Hu GuangyuHu Guangyu was fined EUR 14,400 by the Garante. The authority found inadequate simplified information on video surveillance and retention of recorded images beyond the permitted period.ITGaranteGDPR€14,400
12 Oct 2017Antea Service soc. coop.Antea Service soc. coop. was fined by the Garante 10,000 EUR for unlawfully processing biometric data of employees. The data were used to monitor workplace attendance. The case concerns a breach of personal data protection rules in an employment context.ITGaranteGDPR€10,000
12 Oct 2017Roma Gestioni s.r.l.Roma Gestioni s.r.l. was fined EUR 30,000 by the Garante. The authority found that the company retained surveillance footage longer than permitted under privacy rules.ITGaranteGDPR€30,000
11 Oct 2017SANTANDER CONSUMER EFC, S.A.SANTANDER CONSUMER EFC, S.A. was fined by the AEPD for sending promotional SMS messages without the recipient’s consent. The authority also noted that the messages were sent despite the recipient’s objection to receiving advertising.ESAEPDePrivacy€8,000
05 Oct 2017Regione autonoma Valle d'AostaRegione autonoma Valle d'Aosta was fined by the Garante 100,000 EUR for publishing a regional council resolution on its institutional website that contained an employee’s personal data. The document included professional evaluations and transfer details.ITGaranteGDPR€100,000
05 Oct 2017Start S.p.A.Start S.p.A. was fined by the Garante 40,000 EUR for operating a geolocation system on its buses without full compliance with data protection rules. The case concerned location data processing without the required legal basis and safeguards.ITGaranteGDPR€40,000
05 Oct 2017Comune di CivitavecchiaComune di Civitavecchia was fined by the Garante for unlawfully transmitting sensitive data revealing the health status of disabled students to service providers without a proper legal basis. The authority found that the processing breached data protection and confidentiality requirements.ITGaranteGDPR€30,000
05 Oct 2017Regione autonoma Valle d'AostaRegione autonoma Valle d'Aosta was fined by the Garante for publishing a regional council resolution on its website that contained personal evaluations and information about an employee. The authority found this to be a breach of data protection rules.ITGaranteGDPR€20,000
05 Oct 2017Italprest di Luca Bosimini & C. s.a.s.Italprest di Luca Bosimini & C. s.a.s. was fined €10,000 by the Garante. The authority found that the company failed to implement minimum security measures, including the use of passwords shorter than eight characters, in breach of Article 33 of the Italian Data Protection Code.ITGaranteGDPR€10,000